Re: [patch] alignment trap in hcid
Frédéric Dalleau <[email protected]>
| Newsgroups | gmane.linux.bluez.devel |
|---|---|
| Message-ID | <[email protected]> |
Damn me, I always forget this space after ifs... Is there any way to test this, or hope it's ok ? Frederic Johan Hedberg wrote: > On Feb 29, 2008, at 20:27, Marcel Holtmann wrote: > >>> I recently met an alignment trap in hcid. >>> Some device sent me an sdp request and the answer had to be >>> fragmented because the device reception buffer was very small. >>> After that i saw alignment trap. >>> The last trace I saw was : Continuation state size: 8 >>> The trace is located at sdpd/request.c : static sdp_cont_state_t >>> *sdp_cstate_get(uint8_t *buffer) >>> This function returns an unaligned pointer. >>> >> this is so funny since I know it was there, but the new qualification >> tests don't find it anymore :) >> >> Please fix the coding style. You are missing some spaces after the >> "if". >> >> Johan, please have second look at the patch. It looks good to me. >> > > Looks good to me too. > > Johan > > ------------------------------------------------------------------------- > This SF.net email is sponsored by: Microsoft > Defy all challenges. Microsoft(R) Visual Studio 2008. > http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ > _______________________________________________ > Bluez-devel mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/bluez-devel > ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Bluez-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/bluez-devel
upf_hcid_align.patch
(text/x-patch, 1.2 KB)
diff --git a/sdpd/request.c b/sdpd/request.c
index 20e68b6..5e3c715 100644
--- a/sdpd/request.c
+++ b/sdpd/request.c
@@ -179,7 +179,10 @@ static sdp_cont_state_t *sdp_cstate_get(uint8_t *buffer)
pdata += sizeof(uint8_t);
if (cStateSize != 0) {
- sdp_cont_state_t *cstate = (sdp_cont_state_t *)pdata;
+ sdp_cont_state_t *cstate = malloc(sizeof(sdp_cont_state_t));
+ if (!cstate)
+ return NULL;
+ memcpy(cstate, (sdp_cont_state_t *)pdata, sizeof(sdp_cont_state_t));
debug("Cstate TS : 0x%lx", cstate->timestamp);
debug("Bytes sent : %d", cstate->cStateValue.maxBytesSent);
return cstate;
@@ -408,6 +411,8 @@ static int service_search_req(sdp_req_t *req, sdp_buf_t *buf)
}
done:
+ if (cstate)
+ free(cstate);
if (pattern)
sdp_list_free(pattern, free);
@@ -593,6 +598,8 @@ static int service_attr_req(sdp_req_t *req, sdp_buf_t *buf)
buf->buf_size += sizeof(uint16_t);
done:
+ if (cstate)
+ free(cstate);
if (seq)
sdp_list_free(seq, free);
if (status)
@@ -754,6 +761,8 @@ static int service_search_attr_req(sdp_req_t *req, sdp_buf_t *buf)
}
done:
+ if (cstate)
+ free(cstate);
if (tmpbuf.data)
free(tmpbuf.data);
if (pattern)